Back to Jobs
Development 1h ago

Lead Attack Engineer - Vulnerability Research

United StatesUnited States
Full-time
$235,000 - $265,000 annually
Senior-Level

Job Description

Key Skills Required

Master these to land this role

DevOpsBestseller 🔥
Learn in 63 Hours
PythonBestseller 🔥
Learn in 56 Hours
CybersecurityReverse EngineeringExploit Development

Want to know if you're a match for this job?

Calculate My Match Score

What You’ll Do

Leadership & Team Development

  • Lead, mentor, and grow a team of Attack Engineers specializing in vulnerability research, reverse engineering, and exploit development.

  • Manage a diverse team across multiple seniority levels (from junior engineers to Principal Attack Engineers), ensuring appropriate career development, mentorship, and growth paths for each.

  • Set technical direction, priorities, and quality standards for vulnerability research and attack module development.

  • Foster a culture of continuous learning, raising the bar for offensive rigor, delivery quality, and secure software development practices.

  • Drive hiring and organizational scaling as the Vulnerability Research team expands.

Vulnerability Research Strategy & Execution (Hack, Fix, Verify, Repeat)

  • Own the delivery strategy across vulnerability research, patch-diffing, and rapid N-Day weaponization.

  • Guide the development of end-to-end exploit methodologies:

    • Oversee the reverse engineering of application binaries and patches (Java, C#, .NET, native binaries).

    • Ensure the rapid and safe development of proof-of-concept (PoC) exploits for integration into the core product.

    • Oversee the acquisition and configuration of test systems for exploit development and attack scenario validation.

  • Ensure NodeZero capabilities remain cutting-edge by maintaining a comprehensive global view of emerging vulnerabilities and the latest threat landscape.

  • Create tight feedback loops to ensure reverse-engineered exploits are swiftly weaponized and integrated into NodeZero.

  • Manage operational cadences and ensure the team is prepared to rapidly respond to high-priority emerging vulnerabilities.

What You’ll Bring

Leadership

  • 2-3+ years of direct people management experience

  • 3+ years of software development experience

  • 5+ years leading offensive security, vulnerability research, or red teams.

  • Experience hiring and interviewing engineers

  • Proven ability to balance hands-on technical depth with strategic leadership.

  • Strong technical writing and communication skills, capable of conveying complex exploits to both technical and non-technical audiences.

Vulnerability Research & Attack Surface Expertise

  • Deep expertise in vulnerability research, reverse engineering, and exploit development.

  • In-depth knowledge of common exploitation techniques (e.g., SQL injection, path traversal, buffer overflows).

  • Strong understanding of network protocols, virtualization technologies, and their role in exploitation vectors.

  • Experience with reverse engineering technologies like IDA or Ghidra.

Technical / Engineering Fluency

  • Strong background in production software engineering, ideally in Python.

  • Familiarity with secure software development practices, Git version control, and effective team workflows.

  • Ability to evaluate technical designs and ensure high-quality, production-safe software.

  • Experience working with database systems like Postgres or Neo4j.

Desired Skills

  • Experience with vulnerability disclosure processes (e.g., published CVEs) or bug bounty programs.

  • Familiarity with additional programming languages such as C, C++, Rust, or Assembly.

  • Knowledge of containerization technologies like Docker and Kubernetes.

  • Experience working with cloud environments (AWS, etc.) and large-scale software projects.

  • Relevant security certifications (e.g., OSCP or equivalent) are a plus.

Travel Required

We are a fully remote company, and this job may require up to 10% travel.

How would you rate this job post?

See what other professionals think about this role.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More